Impact
The vulnerability allows anyone with network access to the keploy agent control-plane HTTP server to obtain TLS session keys and traffic data without authentication. Attackers can use the /agent/pcap/keylog endpoint to retrieve NSS keylog lines, decrypt recorded TLS traffic, and also access /agent/stop and /agent/storemocks to interfere with recording sessions. This results in a breach of confidentiality and potential manipulation of the agent’s operation.
Affected Systems
Keploy agent versions from 3.1.0 through 3.6.25 are affected. The issue stems from the agent control-plane server binding to all network interfaces without enforcing authentication, exposing sensitive endpoints.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS information is not available, but the lack of authentication and exposure of all interfaces make exploitation straightforward for anyone who can reach the agent. The vulnerability is not listed in CISA KEV, but its impact is significant due to the ability to decrypt TLS traffic and alter agent behavior.
OpenCVE Enrichment